2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-1551MEDIUM6.1Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the...
CVE-2024-1550MEDIUM6.1A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user'...
CVE-2024-1549MEDIUM6.1If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potenti...
CVE-2024-1548MEDIUM4.3A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led ...
CVE-2024-1547MEDIUM6.5Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another we...
CVE-2024-26267MEDIUM5.3In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 befo...
CVE-2024-26265MEDIUM6.5The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 ...
CVE-2024-25610MEDIUM5.4In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 befor...
CVE-2024-1661MEDIUM5.5A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719. Affected by this vulnerabi...
CVE-2024-25609MEDIUM6.1HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 be...
CVE-2024-25608MEDIUM6.1HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 be...
CVE-2024-25605MEDIUM5.3The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 ...
CVE-2024-25604MEDIUM6.5Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3,...
CVE-2024-25974MEDIUM5.4The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload...
CVE-2024-25973MEDIUM5.4The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker wit...
CVE-2024-25150MEDIUM4.3Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported v...
CVE-2024-25149MEDIUM5.4Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 befor...
CVE-2024-1559MEDIUM6.1The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in ...
CVE-2024-1510MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-21890MEDIUM6.5The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last charac...
CVE-2024-26129MEDIUM5.3PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vu...
CVE-2024-25640MEDIUM5.4Iris is a web collaborative platform that helps incident responders share technical details during investigations. A sto...
CVE-2024-25634MEDIUM6.5alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other...
CVE-2024-25983MEDIUM5.3Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard ...
CVE-2024-25981MEDIUM5.3Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now